Junglewise Threat Intelligence

CVE-2026-43822: Apple multiple operating systems use after free memory corruption

CVE-2026-43822 · Severity: info · CVSS 5.5 · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A memory management vulnerability exists in Apple's operating systems, including iOS, macOS, and watchOS. A malicious application installed on a device could exploit this flaw to cause the system to crash or terminate unexpectedly. This could lead to data loss or disruption of service for the user.

Technical details

A use-after-free (UAF) vulnerability was identified in multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue stems from improper memory management during certain system operations. A locally installed application can trigger this vulnerability to cause a denial-of-service (DoS) condition via unexpected system termination. Apple has addressed the issue by improving memory management in the latest software updates. No user interaction beyond running a malicious app is specified, though the attack vector is local.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats